yashar@devsecops:~
40 containers · CDN-only origin
DevSecOps · Infrastructure · Security

YasharBasiralolomi

// DevOps Engineer & Security Researcher

I design, secure, and operate the infrastructure that keeps mission-critical systems online — and I build and run the products that live on it.

40
containers in production
16
*.yashar.cloud hostnames
4 live
products I built & run
0
direct-to-origin hits after firewall
01 / About

From the wire to the pipeline

DevOps engineer and security researcher with deep roots in Linux systems, IT infrastructure, and automation. I moved from traditional networking and systems work into modern CI/CD pipelines and cloud-native operations — and I've carried a security-first mindset the whole way.

By day I run banking-grade infrastructure. On my own platform I go end to end: I design the architecture, write the services, harden every layer from the CDN edge down to the container, and operate them in production with monitoring, backups, and runbooks. This site documents that work — the high-level and low-level design of each service and the security model behind all of it.

# profile.env
roleDevSecOps Engineer basedTehran, Iran focusCI/CD · IaC · containers · hardening buildsNext.js · Fastify · FastAPI on_callready englishfluent statusavailable
02 / Experience

Deployment log

Three releases of a career, shipped in sequence — from network administration to owning banking-grade infrastructure and security.

v1.0 ✓ deployed

Network Administrator

Iran Ketab Company·Part-time·2021–2022
  • Designed, configured, and maintained company LAN/WAN infrastructure for reliable, secure connectivity across all departments.
  • Stood up and managed VPN tunnels on MikroTik routers for secure remote access across employees and branch offices.
  • Deployed VoIP systems to streamline communications and cut operational costs.
  • Monitored performance and security — patching, updates, and preventive maintenance — and managed switches, routers, and firewalls to policy.
v2.0 ✓ deployed

DevSecOps Engineer & Infrastructure Engineer

AmnAfzarGostarSharif·Part-time·2022–2024
  • Ran IT infrastructure across physical and virtual environments — HP ProLiant G9/G10 servers and high-performance VMware/vSphere clusters — for scalability, security, and high availability.
  • Automated workflows with Terraform, Ansible, Jenkins & GitLab CI/CD, Docker & Kubernetes, plus SonarQube, Nexus, and Harbor for secure code and artifacts.
  • Architected end-to-end monitoring, logging, and alerting (ELK, Prometheus + Grafana) to catch issues before they escalated.
  • Led development and deployment of ParsMAV, a multi-antivirus project — containerized AV environments built and shipped through automated Bash pipelines.
v3.0 ● running

DevSecOps Engineer & Infrastructure Engineer

Smart Rahand Company·Full-time·2024–present
  • Architected and manage mission-critical infrastructure for four major banks — Mehr, Sina, Eghtesad Novin, and Sanat-o-Madan — under strict availability and security compliance.
  • Own a three-phase deployment process (build, test, CD) for banking web portals, mobile apps (PHP, Flutter), and PWAs — including code reviews, security audits, and delivery to Nextcloud and MinIO.
  • First point of contact for SOC/NOC — investigating and resolving misconfigurations, CVEs, and bug-bounty findings in real time.
  • On-call incident response, custom Dockerfiles and Kubernetes manifests, and administration of Oracle DB, Oracle Guard, and Oracle APEX with backup integrity and performance tuning.
03 / Projects

Products I built and run

Each one is designed, coded, containerized, hardened and operated by me on the platform below. Every project links to its full HLD, LLD and security notes.

Nabzنبض

nabz.yashar.cloud ↗
● live

Live financial-market dashboard and token-protected REST API for Iranian gold, coins, currencies and bourse indices, plus crypto and global markets. Persian, RTL, mobile first.

  • Provider failover with circuit breakers, validation and a deviation guard — bad ticks never reach users.
  • Stale-while-revalidate reads: requests never wait on an upstream provider.
  • Browser never holds an API credential — a BFF attaches it server side.
Next.jsFastify 5PostgreSQL 17Redis 7OpenAPIPrometheus
37 backend testsview HLD / LLD →

Spendly

spendly.yashar.cloud ↗
● live

Upload a PDF bank statement; Spendly extracts every transaction (text or scanned, English and Persian), categorises it and shows where the money went — with reports and a private AI assistant.

  • Format-agnostic parser: Persian digits, Jalali dates, OCR, duplicate-safe re-imports.
  • Local LLM (llama.cpp) on a network with no gateway — nothing leaves the server.
  • Learns from corrections; recurring payments, transfers, insights, PDF/CSV reports.
FastAPIRQ workerNext.js 16PostgreSQLRedisllama.cppTesseract OCR
120 backend testsview HLD / LLD →

HamrahPayهمراه‌پی

hamrahpay.yashar.cloud ↗
● live

Lets Iranian users buy ChatGPT, Claude, Cursor and other AI subscriptions without an international card, paying card-to-card in Toman. Admin panel, order flow and live FX pricing.

  • AES-256-GCM envelope for sensitive order data, with key IDs for rotation.
  • Decimal-only pricing engine with per-order price snapshots.
  • Automated, restore-tested backups surfaced in the admin health page.
Next.js 16PostgreSQL 17DrizzleDocker secretsTOTPVitest
Persian / RTLview HLD / LLD →

Secure Admin Access

termix.yashar.cloud · private
● live

A browser-based SSH console for the lab, deployed so that the SSH keys sit behind seven independent layers — and, along the way, the whole origin locked down to CDN-only traffic.

  • CDN → host firewall → nginx guard → rate limit → Authelia 2FA → app login + TOTP → encrypted store.
  • Origin IP drops every non-CDN connection; CDN ranges refreshed daily with safety checks and auto-rollback.
Autheliaiptables / ipsetnginx realipArvanCloud WAFsystemd timers
infra case studyview HLD / LLD →

more/Also shipped

Kelaro ↗● live

Product I built and run, served at kelaro.net.

PFS v1 → v2earlier

Persian inventory & finance SaaS. v1 on FastAPI + React with schema-per-user tenancy; v2 rewrite on Next.js + Laravel, plus a static landing site.

Task Managerearlier

Daily work log that turns entries into formal Persian management reports via an LLM and delivers them on WhatsApp — daily, weekly, monthly.

04 / Architecture

High-level & low-level design

The HLD shows the components, networks and trust boundaries. The LLD shows how each piece actually behaves — data flow, schemas, failure handling, config. Diagrams reflect what is running in production.

One self-hosted platform, many stacks. A Proxmox hypervisor runs the main Docker host; every service is its own Compose project behind a single hardened edge. Exactly one container per stack touches the shared edge network — databases and caches never do.

Proxmox VEUbuntu 24.04Docker 29Compose v5
HLD request path & trust zones
clientinternet
Browsers · API clients · mobile HTTPS only — every hostname resolves to the CDN, never to the origin
edgethird party
ArvanCloud CDN + WAF anycast · DDoS absorption · sets ar-real-ip
16 *.yashar.cloud recordsWAF rulesorigin IP hidden
perimeterhost kernel
iptables DOCKER-USER + ipset NEW tcp/80,443 from outside the CDN ranges → DROP · LAN allowed · SSH LAN-only
daily range refreshatomic ipset swappersisted across reboot
proxyNginx container
Edge Nginx one vhost per service · reverse proxy by container name
TLS 1.2/1.3 · ECDSA wildcardrealip from CDN onlynon-CDN peer → 444limit_req / limit_connHSTSJSON access logscatch-all default_server
identityforward-auth
Authelia SSO nginx auth_request on admin tools · default policy deny
two_factorgroup:adminsban by user + IPargon2id
workloadsdocker networks
products
public · app-level auth
nabzFastify + Next
spendlyFastAPI + LLM
hamrahpayNext + PG
portfolionginx:alpine
admin tools
Authelia 2FA in front
termixweb SSH
portaineradmins only
vaultwardenpasswords
cve-scannerown host
wudimage updates
platform
dev & collaboration
gitlabSCM
gitlab-runnerCI
nexusartifacts
nextcloudfiles
docmostwiki
vikunjatasks
homepageportal
observability
metrics · logs · uptime
alloylog shipper
lokilog store
prometheusmetrics
cadvisorcontainers
nginx-exporteredge
grafanadashboards
uptime-kumauptime
LLD how the platform is wired

networks & isolation

  • homelab — the shared edge network. Exactly one container per stack joins it (web or stack-nginx).
  • security — Authelia, Loki/Alloy, the Docker socket proxy, the edge and Grafana.
  • Per-stack private networks; data networks are internal: true (no route in or out).
  • Separate egress networks for the only containers that must call the internet.
  • No host ports for any product stack — the edge reaches containers by name.

edge nginx

  • Custom image, one conf.d vhost per service, shared includes for CDN guard and forward-auth.
  • Wildcard Let's Encrypt cert (ECDSA P-256) via acme.sh DNS-01 — renewal never depends on ports 80/443 being open.
  • resolver 127.0.0.11 + variable proxy_pass so the edge still boots when one upstream is down.
  • Explicit default_server: unknown hosts and bare-IP hits get a 404/444, never an app.
  • stub_status on a dedicated listener only reachable from the Docker network.

logs & metrics pipeline

nginx ─ access_json.log ─▶ alloy ─▶ loki ─▶ grafana
   fields: status, host, upstream time, TLS cipher,
           via_cdn, edge_addr   # labels: status, server_name only
nginx-exporter ┐
cadvisor       ├─▶ prometheus ─▶ grafana + alert rules
nabz /metrics  │   # app scrapes use bearer tokens
hamrahpay      ┘
  • Only low-cardinality fields become Loki labels; IPs and URIs stay in the log line.
  • cAdvisor keeps only the Compose labels dashboards filter on.

delivery & supply chain

  • Self-hosted GitLab CE + Runner; every product lives in its own repo.
  • Nexus as artifact and Docker registry.
  • Security-relevant images pinned by tag and digest; app images versioned (:1.0.0).
  • WUD tracks image updates; a separate CVE scanner host reads container metadata through a read-only Docker socket proxy (POST=0).
  • All builds and tests run in containers — no language toolchains on the host.

change management

  • Every edge or config change takes a timestamped backup first and ships with a one-line rollback; nginx -t gates every reload.
  • Each larger change produces a deployment report and runbook: request flow, research findings, verification steps, and what was deliberately not changed.
  • Compose healthchecks on every stateful service; dependants start only on service_healthy.
05 / Security

How I handle security

Defense in depth, applied the same way to every service: assume each layer can fail, and make sure the next one still holds. Below is the model, then real findings from my own platform and how I closed them.

L0
EdgeCDN · WAF · DNS
  • All public hostnames resolve to the CDN's anycast network — the origin IP is never published.
  • WAF and volumetric DDoS absorbed before traffic reaches the host.
L1
Host perimeteriptables · ipset · router
  • New 80/443 connections from anything but CDN ranges are dropped in the kernel.
  • SSH is reachable from the LAN only; the router blocks it from the internet.
  • Rules persisted and re-applied at boot; ipset restored before rules load.
L2
Edge proxynginx
  • Second CDN check on the TCP peer (444); real IP trusted from CDN ranges only.
  • TLS 1.2/1.3, HSTS, server_tokens off, catch-all default server.
  • Per-vhost rate and connection limits keyed on the real IP, with stricter zones for login endpoints; body-size caps.
  • Internal endpoints (/metrics, /ready) return 404 at the edge.
L3
IdentityAuthelia SSO
  • Default-deny access policy; admin tools require password + 2FA and group:admins.
  • Brute-force regulation by user and IP (3 tries / 2 min → 10 min ban).
  • Sessions on the parent domain: 30 min inactivity, 8 h maximum.
L4
Applicationcode I write
  • argon2id passwords; sessions stored as hashes; HttpOnly/Secure/SameSite cookies.
  • CSRF via custom header + Origin; nonce-based CSP; schema validation on every input and output.
  • Tenant isolation enforced in one place and covered by tests; AES-256-GCM for sensitive records.
L5
Container runtimedocker
  • Non-root users, read-only root filesystems, cap_drop: ALL, no-new-privileges.
  • Memory, CPU and PID limits; healthchecks; rotated logs.
L6
Network segmentationdocker networks
  • Databases and caches on internal: true networks; egress granted per container, only where needed.
  • One container per stack on the edge network; no host ports for product stacks.
L7
Secretsstorage · rotation
  • Docker secret files or 600-mode env files, git-ignored; ${VAR:?} makes a missing secret fail fast.
  • Key IDs on encrypted data so keys rotate without downtime.
L8
Supply chainimages · models
  • Digest-pinned images where it matters; update tracking (WUD) and a dedicated CVE scanner.
  • The scanner reads Docker through a read-only socket proxy — it can't start or change anything.
  • Downloaded AI model verified by SHA-256.
L9
Detect & recoverlogs · metrics · backups
  • JSON edge logs (incl. CDN/direct classification) in Loki; Prometheus alerts on auth failures, provider errors, staleness.
  • App audit logs that never contain credentials.
  • Automated backups with restore tests; every config change has a one-command rollback.

audit/Findings on my own platform — and the fixes

F-01 · identityhigh

SSO client IP was spoofable

issueThe CDN appends to a client-supplied X-Forwarded-For, and Authelia reads the first entry. An attacker could pick the IP that gets banned — and rotate it forever.
fixForward only the realip-resolved $remote_addr. Verified with a forged header through the CDN: the logged IP was the true client.
F-02 · edgehigh

Origin reachable without the CDN

issueLogs showed 14 % of recent hits were scanners going straight to the origin IP, bypassing the WAF entirely.
fixTwo independent controls: nginx 444 for non-CDN peers and a kernel-level DROP via ipset. Verified from six external vantage points: connections time out.
F-03 · edgemedium

allow/deny can't enforce a CDN allow-list

issueOnce realip is on, allow/deny see the rewritten client IP — a CDN allow-list written that way silently blocks real users or lets everything through.
fixClassify on $realip_remote_addr (the actual TCP peer) with a generated geo map.
F-04 · edgemedium

Unknown hostnames landed on the login portal

issueWithout an explicit default server, nginx sent every unmatched Host (typos, bare IP, scanners) to the first vhost — the SSO login page.
fixDedicated default_server catch-all with the wildcard cert: clean 404 for strays, 444 for non-CDN peers.
F-05 · secretsmedium

Encryption keys stored beside the ciphertext

issueWhen keys aren't provided, the SSH client generates them and writes them into its own data directory — next to the encrypted database they protect.
fixGenerate keys out-of-band and inject them from a 600-mode env file; the data directory now holds only ciphertext.
F-06 · automationmedium

"200 OK" that isn't the IP list

issueThe CDN's site answers any wrong path with 200 + an HTML page. A naive refresher would write garbage into the firewall and lock the CDN out.
fixStrict validation, count-change bounds, nginx -t with auto-rollback, atomic ipset swap. Tested against 8 failure modes.
3,435
direct-to-origin hits reaching nginx in the sample window before
0
direct-to-origin hits reaching nginx in the same window after
7
independent layers between the internet and the lab's SSH keys
06 / Home Lab

docker ps -a

Everything I self-host on bare metal — a Proxmox hypervisor and a Docker host running ~40 containers, all behind one hardened edge.

Live service dashboard — status widgets and links for everything above

homepage.yashar.cloud ↗
07 / Skills

Running services

The stack I operate day to day, grouped the way it actually runs.

08 / Certifications

Signed & verified

09 / Contact

Open a connection

Let's build something reliable.

Available for DevSecOps, infrastructure, and security engineering roles. The fastest way to reach me is below.

emailybasir158@gmail.com
phone+98 914 466 8569
locationTehran, Iranmail →